Scam websites include fake payment logins, counterfeit stores, government impersonation pages, bogus investment dashboards, task-job portals, and tech-support screens. Many copy trusted logos and look polished on a phone, so design is a weak test.

Check how you reached the page, the full web address, what it asks you to enter, and whether it rushes you to pay. Sample addresses use .example and are illustrative only, not live scam links.

Common scam website examples

Scam website example What it tries to get from you Common warning signs
Fake payment or bank login Passwords, one-time codes, or card details An unexpected security alert, a lookalike address, and urgent account threats
Fake online store Money, an address, and personal details Prices far below normal, countdown timers, copied policies, and no independent reviews
Government or tax impersonation page Social Security, W-2, refund, or bank information An unsolicited refund offer and a domain that doesn't match the agency
Crypto investment website A wallet transfer or repeated deposit Guaranteed returns, a fake profit dashboard, and fees to withdraw
Job or task website An upfront payment or "recharge" Easy earnings, messaging-app recruitment, and money required to unlock work
Tech-support or refund page Remote access, payment, or gift cards Browser pop-ups, fake virus warnings, and demands to call immediately
Lottery, romance, charity, or travel page An advance fee or donation Emotional pressure, unverifiable operators, and unusual payment requests

One page can mix several patterns. A fake store may also push malware through a supposed invoice. A phishing page may send you on to a counterfeit payment form.

Fake PayPal, bank, and shopping-account login pages

Phishing logins copy the sign-in screen of a payment service, bank, retailer, or email provider. The message usually says your account is suspended, a payment failed, or suspicious activity needs immediate verification.

An address such as paypa1-login.example or secure-amazon-account.example is meant to look close enough that you stop reading. Check the entire hostname, not just the brand near the front. In paypal.com.badsite.example, the meaningful domain is badsite.example, not PayPal.

A different domain is not automatically fraudulent. Some companies send you through an outside authentication provider. Confirm that through the company's official app or help center before you type a password.

Typical clues:

Don't investigate with the link in the message. Close it, then open the official app, type the address you already know, or use a bookmark you created earlier. If you entered a password, change it on the real service and anywhere else you reused it. Turn on two-step verification where it's available.

Fake Amazon, eBay, and other online stores

Fake shops can look more finished than older scam pages: product photos, a full catalog, a chat box, testimonials, and a countdown that says the sale ends soon.

The hook is usually the offer. A popular item at an unusually low price, a liquidation story, or a claim that only one item remains. Guidance from the University of Colorado on spotting fake online stores flags prices far below market value, little or no independent review history, and clusters of nearly identical reviews posted close together.

Before you buy, work through the transaction, not the homepage:

  1. The address. Does it match the retailer's real domain, or does it tack on words such as "deals," "support," or "clearance"?
  2. Independent information. Search for the business outside its own site. A store with no presence anywhere else deserves caution.
  3. Contact details. Look for a usable address, phone number, and support email, and see whether the details look copied or incomplete.
  4. Returns and delivery. Read the policies before you pay. Missing, contradictory, or oddly worded terms are a warning.
  5. Payment options. Leave if the site insists on gift cards or cryptocurrency. Those payments can be hard to reverse.
  6. Downloads. Don't open an unexpected invoice attachment or install an extension just to finish an order.

A padlock or https connection does not prove the shop is honest. It generally protects the path between your browser and that site. It does not tell you who runs the site or whether goods will arrive.

.shop, .sale, and .net are not automatically scam domains, and .com is not proof of legitimacy. Judge the whole purchase rather than one suffix.

Fake IRS and other government refund websites

These pages promise an unclaimed refund, tax credit, grant, license, or benefit. A fake tax page may ask for a Social Security number, W-2 information, bank details, or an identity document before it "releases" the payment.

For U.S. tax matters, start at IRS.gov by typing the address yourself. A page that uses the IRS name, official-looking seals, or a government-style color scheme is not enough.

The IRS guidance on fake IRS, Treasury, and tax-related messages says not to reply, click the links, or open the attachments. It directs people to send suspicious emails to [email protected]. For a suspicious text, the IRS gives reporting steps and says the message can also be forwarded to 7726 (SPAM).

If you already typed tax or identity information, a suspicious message by itself does not prove identity theft. Review the IRS identity theft guide for individuals. Depending on what happened, the IRS may tell you to use Form 14039, the Identity Theft Affidavit.

Crypto investment and withdrawal-fee websites

Fake investment pages show deposits, profits, rankings, and testimonials. Those numbers can be invented. A balance on a website is not proof that money sits in an account or that you can take it out.

Watch for guaranteed or unusually high returns with little risk, a "secret" system that supposedly trades for you, pressure to deposit more for a higher membership level, and a fee, tax, or "recharge" demanded before withdrawal. Testimonials that exist only on that site, and a request to send cryptocurrency straight to a wallet instead of through a verifiable, regulated service, belong in the same pile.

Don't send a second payment to recover a supposed investment or unlock a withdrawal. If you already transferred funds, contact the cryptocurrency exchange or service you used right away. Recovery isn't guaranteed. The FTC's guidance on what to do after a scam stresses speed and contacting the payment provider.

Job, task, and work-from-home websites

Task scams often start with a polished jobs page or a recruiter message. The work may be rating products, optimizing listings, or other simple online tasks. Then a dashboard shows earnings and asks you to deposit money, often called a "recharge," so you can keep going or cash out.

A request to pay before you receive work, or to put in your own money to reach wages, is a stop sign. Ignore the recruiter's contact details. Find the company's official website yourself and confirm the opening through a channel you already know.

Be cautious if the conversation jumps from a job board to WhatsApp or another private app, promises high pay for repetitive work with no interview, wants cryptocurrency, gift cards, or a training fee, or asks for identity documents and bank details before you've verified the employer. A website balance is not a reason to send money, even if someone says the payment is refundable.

Tech-support, refund, and business-service impersonation pages

A tech-support scam may show a fake virus warning, lock the browser, or display a number for "Microsoft support." A refund variant claims a company overpaid you and needs remote access or a payment to fix the account.

Close the page. Don't call the number in the pop-up, don't install remote-control software because an unsolicited caller told you to, and don't pay a supposed technician with gift cards or cryptocurrency.

Similar pages impersonate business services. One version says a company profile will be removed unless the owner pays a verification or reinstatement fee. Check the service's official dashboard or help center instead of following the message link.

If you already allowed remote access or installed an unfamiliar program, disconnect the device from the internet if you need to, remove the software with a process you trust, and run a security scan. Change passwords from a separate, trusted device. Contact your bank if financial accounts were reachable.

Signals that don't prove a website is safe

Scammers can copy more than a logo. None of these, on its own, proves a page is legitimate:

One odd detail can have an innocent explanation. Several warning signs together, such as an unsolicited link, an unfamiliar domain, a steep discount, and pressure to use cryptocurrency, are a reason to leave without entering information.

A safer way to check a website before using it

If the page is counting down, threatening you, or calling the offer "limited-time," slow down. Open the company's app or type the address you already know. Don't use the link from the message.

Read the full hostname: spelling, extra words, and the actual domain at the end. Look up contact details, seller reviews, and business information somewhere other than that site. A price far below normal, or a guaranteed return, needs proof you didn't get from the page itself.

Give the smallest amount of identity, account, or payment information the task actually requires. Walk away if the site wants gift cards, cryptocurrency, or another unusual method under time pressure. Don't create an account with a password you use elsewhere, even if you're only testing whether the site is real.

What to do if you paid or entered information

The payment method controls which recovery and dispute options may exist. A card issuer, a bank, a gift-card company, and a cryptocurrency exchange each work differently. None of them guarantees that a scam payment will come back.

Contact the payment provider immediately

Don't wait until the file is complete. Give the provider the website address, date, amount, messages, receipts, and screenshots as you collect them.

Protect your accounts and identity

Change any password you typed on the site, and every account where you reused it. Enable two-step verification, review recent sign-ins, and contact the real company if you submitted a one-time code or recovery information.

If the site received tax information, a Social Security number, or identity documents, follow the IRS identity-theft guidance and watch the related accounts. If you downloaded a file, browser extension, or remote-access program, secure that device before you use it for banking or password changes.

Report the website

Report the fraud at ReportFraud.ftc.gov. For a tax-related email or text, use the IRS reporting instructions. A report won't automatically produce a refund, but it gives agencies information that can help them spot related scams.

Be wary of anyone who contacts you later and promises guaranteed recovery for another fee.

Common questions about scam websites

Can a scam website use HTTPS?

Yes. HTTPS can protect the connection while the site collects your information dishonestly. Still check the domain, what the site is trying to do, how you reached it, and how it wants to be paid.

Is every website with a .shop or .net address a scam?

No. The ending alone doesn't establish fraud. An unfamiliar address plus copied branding, extreme discounts, no independent reputation, and urgent payment demands is much more concerning.

Can I get my money back after using a scam website?

Possibly, depending on the payment method, timing, and facts. Recovery isn't guaranteed. Contact the bank, card issuer, gift-card company, payment app, or cryptocurrency exchange immediately and keep the evidence.

If the page is still open and something feels off, close it. Type the real address or use the official app. If you already sent money or typed a password, start with that payment provider or a password change from a device you trust.